White Hat Cybersecurity in the Age of AI – Chris Evans, HackerOne
Chris Evans, chief hacking officer and CISO for HackerOne, dives into how the white hat cybersecurity community is evolving to address emerging technologies such as artificial intelligence (AI).
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Chris Evans, who's CSO for Hacker One.
It's a community of ethical hackers, and they have a new report out talking about, well, how these folks are kind of expanding their skillset as we get new emerging technologies into the mix. Chris, welcome to show. Thank you very much.
It's a pleasure to be here. So walk us through this report. I mean, um, it seems logical that hackers would follow the emerging technology trends, but are there specific emerging technologies that they're looking at and which ones are maybe getting more attention than others?
Than others? Yeah, absolutely. So I think the, the topic of the day is of course ai.
Everyone's very excited about ai. Um, enterprises are using more and more AI and, uh, hackers are also very excited about ai. Um, whenever there's a new technology, um, hackers just have this, um, history of invariably being creative, of being capable and stepping up to learn that technology and to point the way in how that technology can go wrong, how it can be improved, how it can be used safely.
So, um, AI is no different to other, you know, new technologies that have come along in the past years. Hackers a, uh, continue to lead the way in, in learning about the technology and, um, how we can make it safe for everyone. I think a lot of our issues in security can be traced back to, well, developers don't necessarily have the greatest cybersecurity expertise.
It was always something of an optional training program here and there. And now we have machine learning folks who are other otherwise known as data scientists, creating AI models that at the end of the day are just another type of software artifact. So we starting to see the same issues over and over again, where the folks who create these things don't have a lot of cybersecurity expertise, and we're gonna have to learn the hard way.
Um, yeah, sure. Uh, I, I agree. And, uh, as, as always, um, the way that we, uh, get some of that data on this new technology, what are the challenges with it?
Uh, the hackers, again, they, they lead the way. Uh, they're creative, they're curious. They will, um, they will, they will find the ways in which the technology can be abused, the ways in which it will go wrong in unexpected corner cases.
And, uh, that's a source of information that we can use to sort of put back into the development life cycle at the beginning and do some root causing and analysis and hopefully get this, uh, virtuous feedback cycle that leads to, um, uh, learning and, uh, more secure software. How does that virtuous cycle get established? 'cause I think there's still a little sense of queasiness when people are like, we're gonna invite who to come in and do what, and people are a little bit, uh, shall we say, cautious about that kind of thing.
So how do we make that cycle work? Yeah, great question. So this is the, uh, age old, uh, can we trust hackers?
Question. You know, we're gonna invite who to, to do what I like, I like the way you put it. Um, I do think we're getting to the, getting past the stage almost where we asked, were asking that question.
I mean, that, that question was, um, perhaps valid 10 years ago when hacker powered security was new, um, when, uh, when tech companies were trying it, but not necessarily the Fortune 100 we're trying it. Um, but nowadays the, the technology of, of, oh, well, the, the act of in inviting independent, uh, hackers to help you with your security, uh, is so well established. Um, that I, I, um, I think the question is not can we trust these hackers?
I think the question is, um, are you perhaps a, a little bit negligent if you are not one of the many companies that is now doing this just because the, the results speak for themselves. Um, I'd be happy to, you know, just refresh a couple of headline statistics that are of the results, uh, from the hacker power security report. So, uh, to date, uh, hackers on the Hack Hacker one platform have helped enterprises resolve over 350,000 vulnerabilities.
So within that, that bucket, you know, that's breaches avoided. Uh, and the total, the total payout, um, of rewards to hackers on the hacker one platform has crossed, uh, $300 million now. So, um, we operate at such scale that we can now point to this huge bucket of results that says, yes, uh, you, you can trust the hackers and you will get great results.
Um, bug bounty programs become more commonplace. 'cause I think it used to be, you know, it was something you would hear about a Microsoft or a Google launching, but are you starting to see the traditional average enterprise that's building more software than ever also launching these types of programs? We are, yes.
And that's very exciting. There's definitely a continued upward trajectory of adoption among the Fortune 100, for example, of bug bounty programs. And, um, you know, the reasoning for that is we've got more and more results we can point to that, say, Hey, if you, if you partner with hackers, uh, they will find your liabilities and, uh, they'll find them, uh, before the criminals do, and then you can, uh, uh, fix these, uh, liabilities and become safer and more secure.
And, uh, the more, I think the more stories and examples we get out there, uh, it's having an accelerative effect on, on the remainder of, of enterprises jumping on board. So I remain, um, you know, very excited about the results that bug bounty programs get and, and, and bullish that we're, um, on a, on a increasing adoption curve, sorry, remain really excited to be in this space. We started out talking about ai.
It's one of those things that cuts both ways. Do you think that the hackers are gonna start using AI to go find these flaws in our systems faster, and maybe we can even remediate them faster? Yeah, that's the other side of AI in this space, and I'm glad you've asked that because, um, we are seeing hackers start to use AI tools, uh, to, well, to develop AI tools, uh, and then, then to use them.
Um, one of the, uh, beautiful things about, uh, hacker powered security is that the, the hacker has, um, has the human intelligence and the human, the human, um, the human, uh, can use whatever, whatever creative do they want to get the results required, the results required here, of course, being, finding, um, as many serious vulnerabilities as possible and helping fix them. And, um, there are no real bounds based on, on, on how the humans do that. So if, if an, if a new AI tool makes the human more efficient, the human will will do that.
Um, if, um, perhaps combining AI tools with more traditional tools, you know, whatev whatever is the most effective, and, um, that, that's the power of humans in the loop, the human will, um, you know, find whatever technologies, uh, and emerging technologies exist and use them in the most effective way to, um, improve security, uh, in, in the most, um, in the speediest way possible. It seems to me this ongoing debate about whether or not the bad guys are getting smarter, or is it just that we have more of an attack surface to defend than ever, and, um, there's just more opportunities for man. Yeah, there's definitely a race here.
We've talked a lot about the creativity and, uh, talents of the hacker community, but, uh, the criminal community is not, is themselves not static, right? They're also looking at what new, what tooling and technologies they can adopt here. So there's, there's definitely a, a race element here.
Like the, the criminals are getting, um, stronger, uh, and um, and developing new tactics. Uh, um, uh, but fortunately so's team good, you know, the hackers are doing the same thing, and fortunately, there are more hackers than there are criminals, and that's how we go toe to toe with these criminals. We engage the, uh, the hacking community, um, there and there's, and there's more of them.
And that's how we try to win. Since you bring that up, what makes for a good hacker? I think there's probably people watching this who are gonna be, well, maybe I think I could do this.
But, you know, have you seen any common, uh, traits and behavior patterns that make somebody especially gifted towards hacking? Yes, for sure. Um, all of the best hackers that I know have a certain curiosity to them, they're, they're interested in.
Um, they're the sort of people that when they were, um, uh, when they were a kid, you know, they would take their toys apart to see, to see how, how these things tick, um, and hopefully put them back together again as well. Um, but that, that curiosity, um, to sort of dive into how things work, make, makes a very powerful hacker because once you understand in great detail how something works, maybe you can start to reason about the, the corner cases where it may, um, behave strangely, and then, and that's often where, where the bugs and vulnerabilities lurk. So curiosity is definitely a, a huge trait.
Um, additionally determination, um, like, uh, sometimes you can spend a day, you know, taking something apart, learning how it works, but not really find any angles on, on a, on a security issue. And, um, so one important trait in a good hacker is, uh, if you don't find something one day, you're gonna show up with the same energy and vigor the next day be and, uh, have and exhibit that determination. And eventually, you know, if that combination of curiosity and determination, uh, you'll find something eventually, if you have those two things, Do you think we test enough?
And I asked the question because it seems to me at least we might hack something one day, but then it gets updated the next day and probably five other times before the next quote unquote hacking session comes along. Um, so how do we kinda stay current? Yes, a great question.
Um, when I talk to customers, a lot of customers are very interested in, in ongoing testing, of course. Uh, bug bounty program is one way to get ongoing testing, as in, uh, if you have a bug bounty program, then it's, uh, you know, open all the time for, uh, hackers to, to, uh, show up and, and have a look. Um, uh, we had a story recently in Hacker One where we, um, where we do have a lot of internal testing automatic, but you know, occasionally something slips through.
That's why we have bug bounty programs to catch those things that sit through. So we released a, a new feature, uh, had a, had a bug in it, and it shipped through our testing, and within 24 hours in our Bug bounty program, had had found that regression and sent it along to us, um, so that we could, uh, fix it really quickly. So yeah, I do think ongoing testing is important, and I think, um, bug bounty programs are an important component in any company's arsenal to get that ongoing testing of ex of, uh, external attack surface.
Are there best practices for setting up a bug bounty program? Is there some way to go about doing this that people should be following? Because I think a lot of people are like, well, that sounds great, but I have no idea where to start.
Yeah, thanks for asking that. There are some important, um, best practices, uh, and I, I'll get into a couple of those. Um, hacker one, uh, is an expert at taking an enterprise on that journey towards running a gold standard best of breed bug bounty program.
So, um, when you partner with Hacker one, you're not just partnering with, uh, with hackers, but you're partnering with, uh, hacker one employees who will take you along that journey. And some of the, the things that together, um, we'll work on with the enterprise are, um, un understanding that, um, bug banking program, there's a, there's a product component, but there's also a relationship component. So when you, we talk about engaging hackers, we're talking about engaging, um, you know, real humans.
And as always in, in all human interactions, if you can work on, um, building a warm relationship, um, working together well, that will serve you well in your bug bounty program. And just to make the, the, the findings and the program, um, more effective. And of course, we'll also work with enterprises on the more, um, mechanical side of, of running, uh, getting a program up and running, which is, uh, you know, how to set their bounty levels compared to the, um, relative to the MA security maturity of the company.
Um, which assets are the, the sort of critical assets that must be protected at all costs and therefore, you know, highlighted, um, things like that. So there are a lot of, as well as the relationship building there, there, there's a lot of mechanics there that, um, that will help the enterprise take care of You of course are ciso. So what's that one or two things that you see that just makes you shake your head and go, folks, I think we're better than this, and now come we're, you know, still dealing with these issues?
Yeah, interesting question. Um, as a, as a ciso, I, I like to fix something once. If, if ever I have to fix something the same thing a, a second time, that's the sort of thing that, that makes me, it makes me shake my head.
Um, so yeah, that's to say that when, um, you know, bug Bounty provides an excellent source of information, it Bug Bounty will send you those creative, the creative hacking community will send you those unknown and unknowns that hits you out of left field that you just weren't expecting because it's, there's just some creative brilliance there to find something. Um, but for each of those, it should happen once, right? The first time it happens, you're allowed to be surprised, but then, um, you've got some work to do feeding, um, you know, feeding back into your development life cycle as we talked about earlier.
You have that responsibility to add, um, sort of broad general testing for this new interesting thing that's come in so that ideally, uh, yeah, you, you, you find something once, not twice. All right, well folks, you're here. If you know you were going into some uncharted territory, it is better to go there with somebody who's gonna show you the flaws and help you, rather than somebody who's gonna show you the flaws and exploit you.
Hey, Chris, thanks for being on the show. Thank you. Had a blast.
All right. Back to you guys in the.